The "Leak" of 15 Million Kazakhstanis' Data: How the Mechanism of Digital Disinformation Works

Editor’s Note
On August 11, 2026, the information space was flooded with reports that the personal data of 15 million citizens of Kazakhstan had been put up for sale on the darknet. The source was a post about a dark web listing, which claimed that the seller had obtained the database by hacking the eGov electronic government portal and was now peddling the passport details, phone numbers, and addresses of citizens.
Kazakhstan’s Ministry of Digital Development promptly denied the claims. The agency gained access to the exposed files and stated that no systems had been breached. Instead, the archive was merely a collection of random files and images entirely unrelated to the eGov infrastructure.
GFCN analysts also examined the incident and highlighted several critical details. First, the author of the listing only registered their account in August 2026. Second, the dataset itself was never publicly demonstrated, and a mere mention of eGov hardly constitutes proof. The most likely explanation is that a scammer put a compiled dataset from old leaks up for sale, attributing a high-profile origin to it to make a quick buck.
In this op-ed, Ilya Rybin — a Kazakhstan-based GFCN expert, journalist, and head of the nofake.kz project—discusses how such disinformation campaigns are engineered and why the media unwittingly aids malicious actors.
Scammer Vocabulary and Clickbait Headlines
First and foremost, I would highlight the specific vocabulary used in this listing. Scammers, criminals, or threat actors (we don’t yet know who these people are) perfectly understand how modern media operates. The louder the headline, the greater the impact.

As with a vast number of scam messages, the focus is deliberately shifted toward buzzwords: “state database,” “millions of citizens,” “passports,” and so on. In essence, they craft the perfect headline to go viral online. The principle is simple: the more sensational the description, the higher the likelihood that the message will be widely shared.
The Media as Unwitting Accomplices
This is exactly where the media can unwittingly become a participant in a premeditated scheme. By publishing this material, media outlets lend credibility to the message, and the resulting hype plays right into the threat actor’s hands. If their goal was to sell this allegedly stolen database, then mass reporting and media outlets cross-linking to one another generate added value for the product. Ultimately, if the goal was a sale, a potential buyer might actually believe they are dealing with a genuinely stolen database. If the objective was to incite panic, those very same reposts will inevitably achieve that result.
Therefore, writing “Hackers breached eGov and stole the data of 15 million Kazakhstanis” is, in my view, not entirely accurate. Since the information remains unconfirmed, the mere post about an alleged database hack cannot be treated as a fact. Of course, it’s not our place to lecture other media outlets or offer unsolicited advice, but in this case, I believe headlines must reflect the actual reality of the situation. It would be far more accurate to frame it like this: “Unknown user claims to be selling data of 15 million people, allegedly obtained by hacking eGov.” You have to agree that the perception of these two headlines is vastly different, right?
We must understand that the mere existence of a certain database does not equate to the fact of a hack.
Red Flags for Fact-Checking
Another red flag is the source. The only person making these claims is the very individual who allegedly committed the hack and is trying to sell the data. Clearly, they have a vested interest in convincing others of the database’s value. Therefore, it is essential to verify the source’s reputation: what previous posts they have made, how long they have been registered, and whether there is any background information on this individual at all. If an account was created recently and immediately announces a massive cybercrime, it is a major signal to treat the information with skepticism and conduct in-depth fact-checking first.
And this is precisely where a thorough fact-check of both the persona and the information itself will provide all the answers. What grounds are there to claim that such a database exists and was obtained from the stated source? Is there a data sample? Has an independent expert reviewed it? Does the data structure match the system that was supposedly hacked?
This last question is critical, because if the demonstrated structure of the dataset does not resemble the architecture of that system, it is grounds, at the very least, to consult an information security specialist. In this context, what I mean is that in the eGov database, digital documents are not just sitting in some hypothetical folder named “Kazakhstanis’ docs” as a pile of PDF scans.
The material reflects the personal position of the author, which may not coincide with the opinion of the editors.